216.73.216.6

Unidentified Threat Actor Utilizes Android Malware to Target High-Value Assets in South Asia

· Published 10/12/2024 14:55 · Modified 10/12/2024 15:03

Export JSON

Essential information

Published
10/12/2024 14:55
Modified
10/12/2024 15:03
Tags
2024-12-10 android rat whatsapp
Related entities
5 observables, 7 techniques (mitre), 1 malware

Description

An unknown threat actor has deployed a malicious sample targeting high-value assets in Southern Asia. The malware, generated using the Spynote Remote Administration Tool, was delivered via in multiple attempts. The payload, concealed and operating in the background, exhibits various capabilities including location tracking, contact access, camera control, SMS reading, and file system interaction. The malware also attempts to enable accessibility settings for enhanced control. Analysis reveals obfuscated code and permissions that allow extensive monitoring and data extraction. The attack's sophistication suggests possible involvement of an APT group, though the specific actor remains unidentified. This incident highlights the ongoing use of SpyNote variants in targeted attacks against critical sectors and individuals.

External references